ZeroHour

Indicators of compromise

4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
sha256228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://taThe story behind the intelligence
Cisco Talos
· 14d ago
sha25638d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55sample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://taThe story behind the intelligence
Cisco Talos
· 14d ago
sha2569896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7fcontent.js Detection Name: W32.38D053135D-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://taThe story behind the intelligence
Cisco Talos
· 14d ago
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://taThe story behind the intelligence
Cisco Talos
· 14d ago
sha256a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91tGuard.exe Detection Name: W32.228C316455-95.SBX.TG SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://taThe story behind the intelligence
Cisco Talos
· 14d ago
sha256c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2.exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://taThe story behind the intelligence
Cisco Talos
· 14d ago
domainacemlnd.comssage body to route through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicksASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainacems10.comaped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5% of messages matcheASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainactivehosted.come through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicks do not point at the brASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainadvancefundingboost.comusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefundiASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaincatalystboostfunding.comrbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapiASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaincatalystcapitalharbor.comtcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapitalASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindigitalcapitalboost.comomain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfundingASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindigitalrushcapital.comtcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindirectcapitalboost.comradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalhaASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaindirectcapitalpulse.comuardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalruASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainelevatecapitalrush.comcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainemsd4.comending pool , shaped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5%ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainfundingexpresscapital.comstboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20 (by signature hits) of the 148 finASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardiancapitalway.comourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwavASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardiangrowthfunding.comand the per-domain volume: Sender domain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardianloccapital.cometboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainguardianlocchoice.comtalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainharboradvancefunding.comcefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainonlinedirectfinance.comtedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfundASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainourbusinessloans.comrdianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfundiASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainrocketboostfunding.comrectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapitalASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainthebusinessloanexpress.comgrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainunitedfundingwave.comancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinancASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domainyourlocfunding.compitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalwaASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
urlhttps://<account-id>.acemlnd[s do not point at the brand domain at all – they look like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehosteASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
urlhttps://<brand-subdomain>.activehosted[k like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehosted[.]com/<tracking-token> Most of the flagged messages carriedASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft Security Blog
· 14d ago
domaincaixaentradas1inboxshop.siteft Edge and is downloaded from a distribution domain named "caixaentradas1inboxshop[.]site." An analysis of the files associated with the domain hasBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
The Hacker News
· 14d ago
domaininfect.onlinetion for the Infected Marketplace (aka "Banco de Infects," "infect[.]online"), a platform where the threat actor monetizes initial acBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
The Hacker News
· 14d ago
domaindraw.iosers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious iCounterfeit installers turn routine software downloads into enterprise breaches
CSO Online
· 14d ago
domainnodejs.orgy, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a maliciouAttackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The Hacker News
· 14d ago
domainduckdns.orgLet's Encrypt TLS certificate using the domain m-doxa-apodo.duckdns[.]org and following a unique dynamic DNS naming standard. ShareAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
sha25646ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c648aa4e0425b83c0e863a8fee5 5 178.128.87[.]160 June 19, 2026 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 5 178.128.87[.]160 Table 2. Certificate procurement timelinAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
sha2564e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee523187010c4d38dbf88fcb40bf8 1 165.22.184[.]26 April 20, 2026 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 5 178.128.87[.]160 June 19, 2026 46ac289ce0c13666de616446f5Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
sha2567d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8ture. Date Certificate SHA-256 Hash SANs Host Feb. 27, 2026 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 1 165.22.184[.]26 April 20, 2026 4e218e70afdbb116209ec0ebe8Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
sha25687bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172eccf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe AdditionaAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
sha256a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe99665.22.184[.]26 Brazilian Financial Campaign SHA-256 hashes: a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66eeAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
urlhttp://167.148.195[a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additional Resources Operation EscAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Palo Alto Unit 42
· 14d ago
domainanondns.netnnected back to an attacker-controlled domain ( borertors92.anondns[.]net ). While the attack chain here also involved the ScreenCoRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
domainopik.netl, this IP address was associated with the domain tele-sync.opik[.]net during the month of August. Figure 3: According to VirusTRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
sha25608bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020s. 7a4d7d66502d4260 Malicious ScreenConnect ID 1.vbs SHA256 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020 VBScript file executed through wscript.exe . 2.vbs SHA256 dRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
sha256110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d660 VBScript file executed through wscript.exe . 3.vbs SHA256 110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66 VBScript file executed through wscript.exe . 4.vbs SHA256 dRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
sha25619a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260 VBScript file executed through wscript.exe . 3.vbs SHA256 1Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
sha256de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a4570 VBScript file executed through wscript.exe . 2.vbs SHA256 de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
sha256de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede6 VBScript file executed through wscript.exe . 4.vbs SHA256 de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede VBScript file executed through wscript.exe . Trojan:Script/Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
sha256ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0deDefender Detection for 4.vbs WindowsServiceHost.vbs SHA256 ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de VBScript file executed through wscript.exe . WindowsServiceRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress
· 14d ago
ipv4162.55.0.0an Hetzner’s normal announcement of the surrounding block ( 162.55.0.0/16 ), so under standard BGP route selection it took precedeSecurity Incident – BGP Hijacking
Lobsters · security
· 14d ago
ipv4162.55.80.0TC , a block of IP addresses used by Softaculous services ( 162.55.80.0/24 , part of our infrastructure at Hetzner) was affected bySecurity Incident – BGP Hijacking
Lobsters · security
· 14d ago
md52ec37a7cc8daf20b10e1ad6221061ca5the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a faHoneypot-Omaha and batch.py &#x5b;Guest Diary&#x5d;, (Wed, Sep 2nd)
SANS Internet Storm Center
· 14d ago
domainapp-microsoft-edge.com.cn.]com." Some of the counterfeit websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawioFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainbaidu-pan.com.cnt websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaincalibre-ebook.com.cnbelow - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaincn-drawio.com.cnge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaingehie246.comlure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites are listed below - appFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaingw-sogou.com.cnan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainiualef.netand 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of thFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainkaspersky-lab.hl.cne-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainmindmoster.com.cnawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainocam-pc.com.cnou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainoijfwe.netomains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of the campaign is, as MFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainpc-razerzone.com.cnrsky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainsejda.hl.cnoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zhFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainsteelseries-cn.com.cnocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn TheFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaintranslate-youdao.hl.cnerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelitFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domainzh-diskgenius.com.cnl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelity clones of the legitimatFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News
· 15d ago
domaingov.brt it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pagesMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News
· 15d ago
domainhunt.ioreverse-proxy technique on IIS servers in September 2025 . Hunt.io said in July 2025 that it had found more than 630,000 URLsMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News
· 15d ago
domainregistro.brthorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whetherMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News
· 15d ago
domaincdn.nerat.ccle - /usr/local/virtualizor/zzvirtservice Injected string - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-ratBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
domainconnect.ne-rat.xyzg - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat[.]xyz Injected string - jre-runtime.dat Command-and-control (BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
ipv43.2.9.9anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (ReleasBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
sha25673e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48n the official scanner , whose retrieved-script SHA-256 was 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 when checked on September 2, 2026. Contact support before rBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
sha256b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7oad - /usr/lib/jvm/.cache/jre-runtime.dat Payload SHA-256 - b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7 Marker file - /usr/lib/jvm/.cache/.installed Marker file -BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News
· 15d ago
domainadvancedplacyncement.vu.51[.]x) and 104.37.188[.]94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunioInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainamstardmzsmc.vu94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalfInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainarandasoftzfdware.vuinfrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainavisoretentiunionllc.vudplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaincapitalflwxinancialpartners.vumzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbceaInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaincertififiycationedge.vuavisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainconnectivnqzityltd.vucapitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu excelteInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaincrrbcearegroup.vuners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutionInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaindigitaltrafwwrficsystems.vucationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.Inside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainexceltecbusinessbwpsolutions.vuyltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmiInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domaingenamewwgdiamarketing.vutaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainglobaieflsoftinc.vuxceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltdInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainglobalmixeucbdmodetechnologyinc.vutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainglobalprojectspvtltd.vuglobaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufactuInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainidoej.coml panel host found by pivoting from the phishing page title idoej[.]com Domain of the phishing control panel host found via reverInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainjoinbusinessmanagementconsdjeulting.vubalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[Inside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainkentmanqhfufacturingcompany.vurojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainkleepxrnlinecorporation.vunagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainknsinternacshtional.vuntmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestateInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainmonday.comk the true destination by using an open direct parameter on Monday[.]com's tracking service. When clicked the link routes the victInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainmonttmmlrustcompany.vu[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[Inside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago
domainmtprormtductions.vution[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrapInside Knight Office, a New M365 AiTM Phishing Kit
Huntress
· 15d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.